An Adaptive Encryption-as-a-Service Architecture Based on Fog Computing for Real-Time Substation Communications

被引:9
作者
Zhang, Hua [1 ,2 ]
Qin, Boqin [1 ]
Tu, Tengfei [1 ]
Guo, Ziqing [1 ]
Gao, Fei [1 ]
Wen, Qiaoyan [1 ]
机构
[1] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100876, Peoples R China
[2] State Key Lab Cryptol, Beijing 100878, Peoples R China
基金
中国国家自然科学基金;
关键词
Substations; Computer architecture; Real-time systems; Encryption; Edge computing; Encryption-as-a-service; fog computing; smart grids; substation communications; SMART; SECURITY; INFRASTRUCTURE; ATTACKS; SCHEME;
D O I
10.1109/TII.2019.2948113
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The recent outbreak of industrial cyberattacks indicates that the current industrial network security architecture is under serious challenges. As one of the critical industrial networks, the heterogeneous and real-time substation network lacks compatibility with the conventional cryptography architecture represented by secure sockets layer/transport layer security (SSL/TLS) and public key infrastructure (PKI). To enhance the security of smart substations under the premise of low latency, in this article, we present a novel encryption-as-a-service architecture based on fog computing in this article. The architecture offloads encryption to dedicated devices and makes certificate and key management available through unified web services on the fog and cloud layers. Based on this architecture, we propose MX-SORTS, maximizing security on real-time communication of different services, an algorithm for adaptive configuration of encrypting and signing substation network traffic. By the contrast experiments with the conventional cryptography architecture, we prove that the encryption-as-a-service architecture can significantly improve the real-time and security performance of substation networks.
引用
收藏
页码:658 / 668
页数:11
相关论文
共 36 条
[1]   Fog Computing and Smart Gateway Based Communication for Cloud of Things [J].
Aazam, Mohammad ;
Huh, Eui-Nam .
2014 INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD), 2014, :464-470
[2]  
Agrafiotis I, 2015, COMPUT FRAUD SECUR, P9
[3]  
[Anonymous], ARXIV160606992
[4]  
[Anonymous], EAI ENDORSED T SECUR
[5]  
[Anonymous], RES J ENG TECHNOL
[6]  
[Anonymous], 3360 RFC INT ENG TAS
[7]  
[Anonymous], P 9 INT C COMP ENG A
[8]  
Bonomi F, 2012, P 1 ED MCC WORKSH MO, P13, DOI DOI 10.1145/2342509.2342513
[9]   Decentralized Cloud-SDN Architecture in Smart Grid: A Dynamic Pricing Model [J].
Chekired, Djabir Abdeldjalil ;
Khoukhi, Lyes ;
Mouftah, Hussein T. .
IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2018, 14 (03) :1220-1231
[10]   IEC TC57 security standards for the power system's information infrastructure - Beyond simple encryption [J].
Cleveland, Frances .
2005/2006 IEEE/PES TRANSMISSION & DISTRIBUTION CONFERENCE & EXPOSITION, VOLS 1-3, 2006, :1079-1087